Blogs
-
DMARC
How to Route DMARC Aggregate Reports to a Third-Party Service Without Direct Email Delivery
Direct email delivery for DMARC reports is messy — spam filters, mailbox capacity, firewall rules. Here's how to route reports from your DNS host to a third-party aggregator instead.
-
Deliverability
Why FBL Complaints Persist on Transactional Email Even When Content Is Legitimate
Persistent feedback loop complaints on legitimate transactional email usually come down to one missing header. Here is what causes them and how to fix them.
-
DMARC
Why Your DMARC Reports Show Reject Records for Non-Existent Gov.uk Subdomains
If your DMARC aggregate reports show reject records for gov.uk subdomains you do not own, here is why that happens and what it actually means.
-
Deliverability
How Phishing Sites Are Using Let's Encrypt Certificates on Raw IP Addresses to Bypass Security Filters
Phishing campaigns are using Let's Encrypt certificates on raw IP URLs to evade security filters that historically flagged plain HTTP IPs. Here's how the attack works and what defenders should watch for.
-
DMARC
Why Most Email Gateways Miss Phishing PDFs That Use /OpenAction to Launch Attacker URLs
Email security gateways don't scan PDF action dictionaries by default. A clean-looking PDF with a single /OpenAction pointing to a malicious URL can land in inboxes with no warning.
-
DMARC
Why Publishing p=reject Without sp= Still Leaves Your Subdomains Open to Spoofing
Publishing p=reject without the sp= tag leaves subdomains unguarded at many receivers. Here's why it happens, how attackers exploit it, and the three fixes that close the gap.
-
DMARC
What Happens to Email Authentication When ARC Is Retired?
ARC (Authenticated Received Chain) is being retired from email standards. Here's what that means for forwarded mail, mailing lists, DMARC, and what you should do before the change takes effect.
-
DMARC
Why Your DMARC Aggregate Reports May Not Be RFC 7489 Compliant (And What to Do About It)
Most DMARC aggregate reports contain RFC violations that cause standard parsers to fail silently. Here's what's broken and how to handle it.
-
DMARC
How to Add DMARC Monitoring to Your MSP SIEM Stack (Practical Guide)
MSPs can add DMARC monitoring to their existing SIEM stack using three approaches: native tool APIs, IMAP/SMTP report ingestion, or syslog/webhook forwarding. This guide covers all three with a practical implementation checklist.
-
DMARC
Why Your DMARC Report Shows DKIM Fail and SPF Pass at the Same Time
DKIM fail and SPF pass together in a DMARC report is normal, not broken. Here's what alignment means, why it happens, and what to do about it.